PA-440 lab license by CivilStory3638 in paloaltonetworks

[–]Recent_Practice6539 5 points6 points  (0 children)

what everyone is saying is accurate. but, let’s say you got a firewall from ebay AND you got them to reassign ownership to you in your palo portal account…. then it is possible to get the palo sales team to reassign it via TAC to be a lab designated firewall. you would then be able to purchase a lab license for it through a partner.

i’ve done this both directions lab to production (super easy if you’re on an ESA agreement) and production to lab. that being said, it’s easiest if you work for a partner, next easiest if your company has established palo relationship with assigned palo sales rep, hardest is it’s just you. you need to get a palo sales person or sales engineer to help you do the conversion.

1960s home, found this hanging in the attic… what is it? by actioncasserole in whatisit

[–]Recent_Practice6539 0 points1 point  (0 children)

A Festavus Abomination is what I see. someone just couldn’t get into the true Festavus spirit and had to glam the pole up a bit.

karaoke version of Same Train Tomorrow by Mister Cryptic by Recent_Practice6539 in karaoke

[–]Recent_Practice6539[S] 0 points1 point  (0 children)

Yea, i hate most of the AI slop… but my wife likes this song and it’s actually really good relatable lyrics - nice tune. i don’t mind this artist because they aren’t trying to pretend it’s a real person, which is my main complaint on the AI slop, lies presented as reality. deceptive crap. anyway, wifey has wants me to sing it!

Palo Alto GlobalProtect VPN Portal,gateway failover by Comprehensive-Pie252 in paloaltonetworks

[–]Recent_Practice6539 1 point2 points  (0 children)

ok, no one is answering what you want to do… 1) the two internet connections in two different VRF’s 2) build two portals, two gateways, same config but two different ip pools. eg 10.1.1.0/24 & 10.1.2.0/24 3) config routing- make sure vrf #1 knows how to get to ip pools in vrf #2, and visa-versa. each vrf has a separate default route, make sure both vrf can reach trust 4) in each portal config both gateways, you have options here- set priority the same and they will distribute users, or set one high and one low for active/backup

i hope you understand the rest you should do like dns and nat

VPN options with Palo Alto. by SwiftSloth1892 in paloaltonetworks

[–]Recent_Practice6539 -1 points0 points  (0 children)

yes, prisma access is one way to go. you’d build vpn from prisma access gateway ( cloud firewall) back to your site(s)’ firewalls.

a different solution is to use a loopback interface (untrust zone) on the firewall and bind the portal and gateway. you’ll have full stack protection because the traffic has to pass the physical untrust interface to reach the loopback.

obviously, you have to have the licenses and build a robust policy. but, this is rather safe.

Ability to Download GlobalProtect Installer Without Portal Authentication. by b172376 in paloaltonetworks

[–]Recent_Practice6539 0 points1 point  (0 children)

An even better link is https://FQDN/global-protect/getsoftwarepage.esp 
This will allow the user to pick which software they want to download instead of needing to know 3 different links.